Back to skill

Security audit

portada-video-carrusel-formula100k

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Spanish-language workflow for generating an animated Instagram carousel cover, with expected but sensitive use of user selfies and external media-generation services.

Before installing, confirm you are comfortable with the agent using local or Telegram-provided selfies and uploading them to Higgsfield to generate the cover. Run it in an environment where npm package installation, Chromium with --no-sandbox, Google Fonts access, and Higgsfield credit usage are acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

La descripción presenta una skill integral de portada animada que incluye generación o uso de una foto, animación tipo cinemagraph y entrega de múltiples assets. El código proporcionado implementa solo una parte acotada: la exportación de un elemento HTML (.slide) a PNG transparente mediante Chromium/Puppeteer. Esa porción sí coincide con la parte de 'renderiza el título como PNG transparente con Chromium', pero no respalda la capacidad principal declarada de crear una portada animada ni de entregar el paquete completo. Por tanto, hay una discrepancia material entre el propósito declarado y el comportamiento real del código mostrado.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill explicitly instructs use of environment-dependent tooling and shell commands (command -v, npm install, node, Chromium, ffmpeg, network access) but does not declare any tool scope or allowed-tools boundary. In an agent environment, missing scope declarations can lead to broader-than-expected execution capability, making accidental command execution, data exposure, or policy bypass more likely.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/recetas-higgsfield.md (reported line 24)May include surrounding context.

md
Pasos previos para las selfies locales (cliente CLI, sin widget):
1. `media_upload` con `files:[{filename, content_type:"image/jpeg"}]` → devuelve `upload_url` + `media_id`.
2. `curl -X PUT -H "Content-Type: image/jpeg" --data-binary @archivo.jpg '<upload_url>'`
3. `media_confirm` con `type:"image"` y `media_ids:[...]`.

Carpeta de selfies del usuario, si la tiene configurada: `cerebro/fotos`. Si no existe, pregúntale la ruta.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script’s top-level comments and CLI usage/error strings are written only in Spanish, which imposes a specific language on users without any opt-in or explanation of a justified locale restriction. This matches the policy category for language or locale constraints in natural-language content.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency uses a caret range (^24.42.0), which permits installation of newer compatible versions instead of a single audited version. In build or deployment environments that do not strictly honor a lockfile, this can introduce supply-chain risk by pulling unreviewed upstream changes or a compromised release of puppeteer-core.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
"overlay": "node overlay_export.js"
  },
  "dependencies": {
    "puppeteer-core": "^24.42.0"
  }
}

Static analysis

No suspicious patterns detected.